Samuel Eng's Avatar

Samuel Eng

@samueleng.se.bsky.social

πŸ’Ό Trusted Security Advisor at Onevinn

48 Followers  |  119 Following  |  32 Posts  |  Joined: 06.11.2024  |  2.198

Latest posts by samueleng.se on Bluesky

Blog | Samuel Eng A minimalistic blog built with Next.js, Tailwind, and Shadcn.

πŸ“£ New blog article ⬇️

blog.samueleng.se/posts/2025-1...

Conditional Access Back to Basics - What are "Cloud Apps" and why can't I find my app in the picker?

#conditionalaccess #entra #entraid

29.10.2025 16:10 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Blog | Samuel Eng A minimalistic blog built with Next.js, Tailwind, and Shadcn.

πŸ“£ New blog article

RDP connection to a Microsoft Entra–joined machine using Entra ID cloud account from macOS is not as straightforward as it seems.

blog.samueleng.se/posts/2025-0...

13.10.2025 08:50 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Block password additions is a massive security enhancement πŸ‘

17.09.2025 06:55 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Got it πŸ‘ I really appreciate your response

13.09.2025 08:04 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@danielbradley.bsky.social Really enjoyed the Entra Docs Tracker, great idea, and thank you! πŸ‘ Any plans to open-source it? I’m thinking about other MS Docs repos I’d like to track.

01.09.2025 09:53 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Tagging additional Entra authorities for possible answers πŸ™‚ @fabian.bader.cloud @dirkjanm.io

31.08.2025 16:13 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I see. My initial thought was that the attribute serves as a proxy indicator for the type of service principal (i.e., whether CA can be applied).

29.08.2025 19:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Does anyone know why the Conditional Access app picker applies the filter servicePrincipals?$filter=preferredSingleSignOnMode ne 'notSupported'? Is there any correlation with public vs. confidential clients or web vs. mobile clients? @merill.net @cbrhh.bsky.social @nathanmcnulty.com

29.08.2025 12:01 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0

Well deserved @nathanmcnulty.com! πŸ‘πŸ†

02.05.2025 15:51 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I can confirm that I tried it in my lab tenant, and it is working as expected. πŸ‘

05.03.2025 10:25 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

πŸ‘πŸ‘I admire your dedication πŸ˜„

05.03.2025 10:23 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Out of curiosity, what did you base your announcement on? πŸ™‚

05.03.2025 10:13 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Great news! Are there any updates on Learn or official announcements?

05.03.2025 08:23 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Ping @merill.net πŸ˜€

26.02.2025 10:26 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

@merill.net Maester GitHub actions issue?

17.02.2025 18:46 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Samuel Eng on LinkedIn: #microsoft #microsoftsecurity #sse #sase #privateaccess #passkeys #eam… πŸ“£Β Highlighting two Microsoft Entra products working together - External Authentication Method (EAM) and SSE Private Access (ZTNA) An External Authentication…

πŸ“£Β Highlighting two Microsoft Entra products working together - External Authentication Method (EAM) and SSE Private Access (ZTNA)
www.linkedin.com/posts/samuel...
#sse #sase #microsoft #entra #entraid

05.02.2025 19:13 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Great content! πŸ‘

28.01.2025 16:55 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Excellent news! Is it too much to ask for the inclusion of Workload ID premium features for this app? πŸ˜‚

07.01.2025 14:04 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

πŸ’―agree. Since all network destinations and segments are represented by an app, the possibilities become limitless. Combine this with Entra ID Governance for self-service, approval, access review, and audit trails πŸ”₯πŸ”₯

07.12.2024 09:50 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Search the Microsoft community on Bluesky and get verified! Bluesky account verification for Microsoft staff and MVPs.

Today is the day folks.

The new and updated Bluesky.ms is now live!

Go add yourself. I'll share a detailed step by step...

03.12.2024 22:15 β€” πŸ‘ 172    πŸ” 65    πŸ’¬ 31    πŸ“Œ 11
Preview
How to enable passkeys in Microsoft Authenticator for Microsoft Entra ID - Microsoft Entra ID Learn about how to enable passkeys in Microsoft Authenticator for Microsoft Entra ID.

Thank you for a great video πŸ‘

Entra supports attenstation of the Microsoft Authenticator app (iOS/Android)

iOS: Uses the iOS App Attest service
Android: Uses the Play Integrity API

02.12.2024 17:54 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Once we have native built-in capabilities to remove or scramble the password in Entra, passwordless options for self-remediation of ID protection risks, universal passkey support et.c., everything will come together.

02.12.2024 16:34 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

By the way, am I misunderstanding this? @merill.net

02.12.2024 15:15 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Got it, I appreciate you taking the time to respond.

02.12.2024 15:11 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

A user has a passkey and MS auth app with push registered, and initiates a SSPR. The SSPR wizard suggests verification with app + push (and no other alternatives). Why not the most secure way, using the passkey? Any idea? @merill.net @jeftek.com @nathanmcnulty.com

02.12.2024 14:57 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0

Does @ mentioning work for Linkedin?

24.11.2024 09:04 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0

Would have loved BYOD/unmanaged device support in H1 2025 instead

21.11.2024 18:54 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

MFA requirement for Register security information, using TAP for secure bootstrapping to phishing-resistant authentication methods such as passkeys. This is the way.

13.11.2024 21:59 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Microsoft Entra Private Access for on-prem users | Microsoft Community Hub Enable secure access to private apps that use Domain Controller for authentication  

I’m referring to this capability with a DC agent.

techcommunity.microsoft.com/blog/identit...

13.11.2024 17:11 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Then I guess "On-prem MFA" will require the full SKU?

13.11.2024 13:26 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@samueleng.se is following 20 prominent accounts